CVE-2026-14891: Hashicorp Nomad

High severity, CVSS 8.7. EPSS: 0.5% chance of exploitation in the next 30 days.

HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host path into a container even when volume bind mounts are disabled, potentially leading to reading and writing files on the host. This vulnerability, CVE-2026-14891, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.

Affected products

  • Hashicorp Nomad: from 0.4.1, before 2.0.4 (fixed in 2.0.4)
  • Hashicorp Nomad Enterprise: from 0.4.1, before 2.0.4 (fixed in 2.0.4)

Published 2026-07-08. Last modified 2026-07-09.